Vulnerabilities in GitLab that allow account takeover and executing commands under another user
Corrective updates for the collaboration platform — GitLab 16.7.2, 16.6.4, and 16.5.6 have been released, addressing two critical vulnerabilities. The first vulnerability (CVE-2023-7028), which has been assigned the highest danger level (10 out of 10), allows for the capture of another user's account through manipulation of the forgot password recovery form. The vulnerability arises from the ability to send an email with a code to reset the password to unconfirmed […]
